SCORE™ DATA PROCESSING ADDENDUM (DPA)
Version 1.0
Effective Date: September 3, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Rate Tracker Payments LLC, an Ohio limited liability company ("Rate Tracker," "Processor," "we," "our"), and the customer identified in the applicable Order Form or Terms of Service ("Customer" or "Controller").
This DPA applies only to the extent Rate Tracker processes Personal Data on behalf of Customer in connection with the Score™ platform.
If there is a conflict between this DPA and the Terms of Service or End User License Agreement regarding the processing of Personal Data, this DPA controls.
1. DEFINITIONS
For purposes of this DPA:
Applicable Privacy Laws means all laws governing the processing of Personal Data applicable to the parties, including, where applicable, U.S. state privacy laws and other applicable data protection laws.
Controller means the party that determines the purposes and means of processing Personal Data.
Processor means the party processing Personal Data on behalf of the Controller.
Personal Data means information relating to an identified or identifiable natural person that is protected under Applicable Privacy Laws.
Processing means any operation performed on Personal Data including collection, storage, organization, use, transmission, analysis, deletion, or destruction.
Security Incident means unauthorized access to, acquisition of, disclosure of, or destruction of Personal Data, excluding unsuccessful attempts that do not compromise Personal Data.
2. SCOPE
This DPA applies only to Personal Data processed by Rate Tracker solely for the purpose of providing the Score™ Services.
This DPA does not apply where Rate Tracker acts as an independent Controller under Applicable Privacy Laws.
3. CUSTOMER RESPONSIBILITIES
Customer represents and warrants that:
- it has all necessary rights and permissions to provide Personal Data to Rate Tracker;
- it has provided any required notices;
- it has obtained any required consents;
- its instructions to Rate Tracker comply with Applicable Privacy Laws; and
- it is responsible for the accuracy and legality of Personal Data submitted through the Services.
4. RATE TRACKER RESPONSIBILITIES
Rate Tracker shall:
- process Personal Data only as necessary to provide the Services or as otherwise instructed by Customer, unless required by law;
- ensure personnel with access to Personal Data are subject to appropriate confidentiality obligations;
- maintain commercially reasonable administrative, technical, and organizational safeguards;
- assist Customer in responding to reasonable requests relating to Personal Data where legally required and technically feasible; and
- promptly notify Customer if Rate Tracker believes a processing instruction violates applicable law.
5. PERMITTED PROCESSING
Customer instructs Rate Tracker to process Personal Data for the following purposes:
- hosting the Services;
- authenticating users;
- analyzing financial information;
- generating reports;
- producing Financial Health Scores;
- providing customer support;
- maintaining platform security;
- detecting fraud and abuse;
- maintaining backups;
- performing disaster recovery;
- improving service performance;
- complying with legal obligations.
Rate Tracker shall not process Personal Data for materially different purposes except as authorized by Customer or required by law.
6. SECURITY MEASURES
Rate Tracker will maintain security measures appropriate to the nature of the information processed, taking into account available technology, implementation costs, and the risks involved.
Such measures may include, as appropriate:
- encryption of data in transit;
- encryption of stored sensitive data where appropriate;
- role-based access controls;
- least-privilege administrative access;
- multi-factor authentication for privileged accounts where appropriate;
- logging and monitoring of production systems;
- vulnerability management;
- periodic security testing;
- backup and disaster recovery procedures;
- employee security awareness training; and
- vendor risk management practices.
Rate Tracker may update these security measures over time provided the overall level of protection is not materially reduced.
7. SUBPROCESSORS
Customer authorizes Rate Tracker to engage subprocessors to support the Services.
Rate Tracker shall:
- use reasonable diligence in selecting subprocessors;
- require subprocessors to protect Personal Data through written agreements imposing appropriate confidentiality and security obligations; and
- remain responsible for its obligations under this DPA with respect to processing performed by its subprocessors.
A current list of significant subprocessors will be made available upon reasonable request or through customer documentation if maintained.
8. SECURITY INCIDENTS
If Rate Tracker becomes aware of a confirmed Security Incident affecting Customer Personal Data, Rate Tracker will:
- notify Customer without unreasonable delay after confirming the incident;
- provide available information reasonably necessary for Customer to understand the nature of the incident;
- take commercially reasonable steps to contain, investigate, and remediate the incident; and
- cooperate with Customer regarding legally required notifications, to the extent appropriate.
Notification does not constitute an admission of fault or liability.
9. ASSISTANCE
To the extent required by Applicable Privacy Laws and reasonably requested by Customer, Rate Tracker will provide reasonable assistance regarding:
- requests from individuals concerning their Personal Data;
- security obligations;
- legally required impact assessments where processing by Rate Tracker is directly relevant; and
- consultations with regulators where legally required and applicable to the Services.
Customer remains responsible for responding to requests from individuals unless otherwise agreed.
10. DATA RETENTION AND DELETION
Upon termination of the Services, Customer may request deletion of Customer Personal Data, subject to:
- legal retention obligations;
- backup retention schedules;
- fraud prevention;
- dispute resolution;
- security purposes; or
- other lawful business requirements.
Where deletion is requested and legally permissible, Rate Tracker will delete or anonymize Customer Personal Data within a commercially reasonable period.
11. CONFIDENTIALITY
Rate Tracker shall ensure that individuals authorized to process Personal Data:
- are bound by confidentiality obligations; or
- are subject to appropriate statutory duties of confidentiality.
Those obligations survive termination of employment or engagement.
12. AUDITS
Upon reasonable written request and no more than once annually (unless required following a confirmed Security Incident), Rate Tracker will make available information reasonably necessary to demonstrate compliance with this DPA.
Where appropriate, this obligation may be satisfied through:
- independent audit reports;
- security certifications;
- security questionnaires; or
- similar documentation.
Any audit must:
- occur during normal business hours;
- avoid disruption of Rate Tracker's operations;
- protect confidential information belonging to other customers; and
- be subject to reasonable confidentiality obligations.
13. INTERNATIONAL TRANSFERS
If Personal Data is transferred across national borders, the parties agree to implement appropriate safeguards as required by Applicable Privacy Laws.
14. LIABILITY
Liability arising under this DPA shall be governed by the liability provisions contained in the applicable Terms of Service or EULA unless otherwise required by Applicable Privacy Laws.
Nothing in this DPA limits liability where such limitation is prohibited by law.
15. CHANGES IN LAW
If Applicable Privacy Laws materially change, the parties agree to cooperate in good faith to amend this DPA as reasonably necessary to maintain compliance.
16. SURVIVAL
The obligations relating to confidentiality, data protection, deletion, security, liability, and any provisions intended to survive termination shall remain effective following termination of the Services for so long as Rate Tracker continues to process Customer Personal Data.
17. ORDER OF PRECEDENCE
In the event of a conflict between this DPA and the Privacy Policy, Terms of Service, or EULA regarding the processing of Personal Data, this DPA governs solely with respect to such processing.
18. GOVERNING LAW
This DPA shall be governed by the governing law specified in the applicable Terms of Service unless Applicable Privacy Laws require otherwise.
19. CONTACT INFORMATION
Questions regarding this DPA may be directed to:
Rate Tracker Payments LLC
Partner Success Team
7100 E. Pleasant Valley Road Independence, OH 44131
Support@getscore.io
(440) 829-6062